The g-FFL Cockpit plugin for WordPress is vulnerable to...
Moderate severity
Unreviewed
Published
Dec 6, 2025
to the GitHub Advisory Database
•
Updated Dec 6, 2025
Description
Published by the National Vulnerability Database
Dec 6, 2025
Published to the GitHub Advisory Database
Dec 6, 2025
Last updated
Dec 6, 2025
The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.
References